What does IT support for a DFSA-regulated firm include?
Beyond a helpdesk, it includes secure configuration of identity, devices and Microsoft 365, patching and backup, monitoring, incident readiness and the regular reports that become your evidence. We also help you map these to GEN 5.5.
Can you write our DFSA cyber risk management framework?
We can help draft and maintain the technical parts and supporting procedures. The framework itself must be approved by your governing body and owned by senior management, so we work alongside your compliance officer rather than in place of them.
Does a DIFC firm’s IT provider have to be based in the DIFC?
No. Cre8 IT’s Dubai office is in Jumeirah Lake Towers, and our engineers work on site or remotely depending on the arrangement.
Who is responsible if our IT provider has an incident?
You are. Under GEN 5.3.21, outsourcing does not relieve an authorised firm of its regulatory responsibility. That is why contracts should require prompt incident notification, and why you should supervise the provider.
How long does onboarding a DIFC firm take?
It depends on your size, your current set-up and how much needs fixing. After an initial assessment we agree a plan and dates with you and start with the controls that reduce the most risk.